4 augusti 2026
57 min
Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines.
Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills.
Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.
Sponsorship inquiries:
sponsor@softwareengineeringdaily.com
The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.
Lyssna på fler avsnitt från
Software Engineering Daily
Visar 1–10 av 99 avsnitt
27 augusti 2026
57 min
25 augusti 2026
55 min
20 augusti 2026
73 min
18 augusti 2026
48 min
13 augusti 2026
50 min
11 augusti 2026
48 min
6 augusti 2026
52 min
30 juli 2026
51 min
28 juli 2026
44 min
21 juli 2026
64 min